Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Threat Intelligence Streamlines SOC Triage, Reduces Analyst Burnout
September 22, 2026
New AI Tool Steals Credit Cards, Compromises Retailers
September 22, 2026
AI Malware Tracking Tool Discovers Autonomous AI Malware
September 22, 2026
Home/CyberSecurity News/New AI Tool Steals Credit Cards, Compromises Retailers
CyberSecurity News

New AI Tool Steals Credit Cards, Compromises Retailers

Key Takeaways A sophisticated new AI-powered threat, dubbed “Cairn,” is actively targeting retailers, stealing credit card data and compromising backend systems. The attacks leverage...

Sarah simpson
Sarah simpson
September 22, 2026 4 Min Read
2 0

Key Takeaways

  • A sophisticated new AI-powered threat, dubbed “Cairn,” is actively targeting retailers, stealing credit card data and compromising backend systems.
  • The attacks leverage open-source AI tools, enabling rapid deployment and making the campaign highly cost-effective for attackers.
  • Over 100 e-commerce sites have been identified as infected with card skimmers, with remediation proving challenging and time-consuming for victims.
  • The threat highlights a growing disparity between human-paced cybersecurity defenses and the speed of AI-driven attacks.

AI-Powered Campaign Targets Retailers, Stealing Credit Cards and Corrupting Databases

A new, highly effective AI-driven attack campaign, identified as “Cairn,” is actively compromising online retailers, deploying sophisticated card skimmers, and manipulating backend databases to steal sensitive information. This advanced threat leverages open-source AI tooling, allowing attackers to operate with remarkable speed and efficiency, often gaining initial access within hours and inflicting significant damage before detection.

Table Of Content

  • Key Takeaways
  • AI-Powered Campaign Targets Retailers, Stealing Credit Cards and Corrupting Databases
  • The Modus Operandi: Data Theft and System Compromise
  • Widespread Skimming Operations
  • The Escalating Threat Landscape
  • What You Should Do

The Modus Operandi: Data Theft and System Compromise

In one documented instance, Cairn infiltrated a major online clothing retailer, deploying its AI agent to execute a series of malicious actions. The agent systematically created new tables within the database, then populated them with stolen customer data, including names, addresses, and credit card numbers. This exfiltrated data was subsequently uploaded to a cloud storage bucket controlled by the attackers, effectively siphoning off vast quantities of personal financial information.

A separate incident at a bicycle retailer revealed an even more destructive aspect of the Cairn campaign. After establishing a foothold, the AI agent created temporary staging tables before proceeding to delete a staggering 180 tables. These included critical operational tables and even backup tables meticulously maintained by the company’s own IT administrators, demonstrating a profound level of system compromise and data destruction.

Widespread Skimming Operations

Beyond direct database manipulation, card skimming remains a primary objective of the Cairn campaign. Security researchers, including Varys, have confirmed the presence of these skimmers on 19 named victim sites and have identified over 100 additional infected e-commerce platforms. The skimmers are designed to covertly capture payment card details as customers enter them during online transactions, sending the stolen data directly to the attackers.

The methods used to inject these skimmers vary significantly, adapting to the level of access achieved by the AI agent. Techniques range from appending malicious loaders to legitimate jQuery files, compromising Amazon S3 buckets behind Content Delivery Networks (CDNs), utilizing Kubernetes initContainers, to establishing persistent cron jobs within JBoss log directories. These cron jobs are particularly insidious, re-injecting the skimmer script every two minutes, ensuring persistence even if administrators attempt to clean or redeploy affected systems.

Injected card-skimmer script
Injected card-skimmer script (Image Source: Gambit Security)

The Escalating Threat Landscape

The significance of the Cairn campaign extends beyond the immediate number of victims. Its reliance on open-source AI tooling dramatically lowers the barrier to entry for attackers, with the marginal cost of operations estimated to be in the tens of dollars. This affordability, combined with the rapid pace of compromise—often less than a day to gain access—presents a stark contrast to the weeks, and sometimes months, required for remediation in complex enterprise environments.

The current cybersecurity landscape is already strained, with over 600 critical vulnerabilities reported monthly across major vendors. Approximately 87% of exploited flaws are targeted before or at the time of public disclosure. Traditional human-centric security operations, with their calibrated detection thresholds, change windows, and on-call rotations, are struggling to keep pace with the machine-speed of AI-driven attacks. A recovery plan that merely focuses on database restoration is no longer sufficient to address these evolving threats.

Gambit Security, the firm tracking the Cairn campaign, has reportedly notified many affected organizations and collaborated with the Shadowserver Foundation and Cloudflare to disrupt the attacker’s infrastructure. However, the operator has demonstrated resilience, repeatedly rebuilding their command and control systems, indicating that the campaign remains active and ongoing.

What You Should Do

  • Implement Advanced Threat Detection: Deploy AI-powered anomaly detection systems that can identify unusual database activities, file modifications, or network traffic patterns indicative of compromise, rather than relying solely on signature-based detection.
  • Strengthen Access Controls: Enforce strict least privilege principles for all users and services accessing production systems and databases. Regularly audit and review access permissions.
  • Regularly Backup and Isolate Data: Perform frequent, immutable backups of all critical data and store them in isolated, off-network locations to ensure recoverability in the event of a database compromise or deletion.
  • Monitor for Skimmer Injections: Implement continuous monitoring for unauthorized modifications to website files, particularly JavaScript files, and server configurations that could facilitate card skimmer injection. Utilize Content Security Policies (CSPs) to restrict script sources.
  • Incident Response Readiness: Develop and regularly test a comprehensive incident response plan specifically tailored for data breaches and system compromises involving AI-driven threats. This should include rapid containment, eradication, and recovery procedures.
  • Patch and Update Proactively: Maintain a rigorous patching schedule for all software, operating systems, and web applications to mitigate known vulnerabilities that attackers might exploit for initial access.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitSecurity

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

AI Malware Tracking Tool Discovers Autonomous AI Malware

Next Post

Threat Intelligence Streamlines SOC Triage, Reduces Analyst Burnout

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New TASK#STOMP Backdoor Steals Documents and Wi-Fi Passwords via PowerShell
September 22, 2026
Critical Red Hat OpenShift Flaw (CVE-2024-XXXX) Lets Attackers Bypass PGP Checks
September 22, 2026
Critical Veeam Agent for Windows Flaw (CVE-2023-27532) Actively Exploited
September 22, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us